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THE EMBODIMENTS OF THE INVENTION IN WHICH AN EXCLUSIVE PROPERTY 
OR PRIVILEGE IS CLAIMED ARE DEFINED AS FOLLOWS: 




A system fc\s marching electronic data files stored in a data repository system, comprising: 
a o^mmunicativ^^ environment housing 

(i) \a first ageniyprogram for a depositor computer of an electronic data file in the data 
^sitory system and 

(ii) a second agent program for a first user computer with access privileges to the 
electronic data file; 



a manifest for the electronic date file listing access controls for the electronic data file, the 
manifest being accessible to and n^ptainbd by the first agent program; 



a first record of the first user 
first record being accessible to and mainta- 



>mpiiter's access privileges to the electronic data file, the 
aed ov the second agent program; 



means to communicate changes to the\iai^fest affecting the first user computer's access 
privileges to the electronic data file from the first a^eK* program to the second agent program for 
updating the first record; and 

means for the first agent program to verify the fih^ ;iser computer's access privileges to 
the electronic data file before the electronic data file is release^:) the second agent program. 



2. The secure system, according to claim 1, wherein the first agent program is a secure 
extension of the depositor computer and the second agent program is a\ecure extension of the 
first user computer. \ 



CA998-040 

The secure system, according to claim 2, further comprising means for communicating the 
changes to the manifest affecting the first user computer's access privileges to the electronic data 
file from the second agent program to the first user computer. 



4. The secure system, according to claim 2, further comprising: 

a third agent program for a second user computer with access privileges to the electronic 
data file; and 

a second record ofc^he second user computer's access privileges to the electronic data file, 
the record being accessible to^and maintained by the third agent program, 

and wherein the means to commuhjcate changes to the manifest affecting the first user computer's 
access privileges to the electronic o^ta file from the first agent program to the second agent 
program for updating the first record, comprises means to communicate changes to the manifest 
affecting the second user computer's access privileges to the electronic data file from the first 
agent program to the third agent program for iWating the second record; and 

wherein the means for the first agent program to verify the first user computer's access privileges 
to the electronic data file before the electronic data fik is released to the second agent program, 
comprises means for the first agent program to verifV the second user computer's access 
privileges to the electronic data file before the electronic da^a file is released to the third agent 
program. 



5. The secure system, according to claim 4, wherein the third agent program is a secure 
extension of the second user computer. 



6. The secure system, according to claim 5, further comprising means for communicating the 
changes to the manifest affecting the second user computer's access privileges to\he electronic 
data file from the third agent program to the second user computer. 
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The secure system, according to claim 5, wherein the communication environment 
iprises a server. 

8. The secure system, according to claim 5, further comprising an interface to the data 
repository system housed in the communications environment, the interface adapted to receive all 
communication^ and from the data repository system and the agent programs. 

9. The secure systeh}, according to claim 8, wherein the interface is a secure extension of the 
data repository system. 



10. A process for maintaining a^ecure electronic data search system for an electronic data 
repository, the system havtfig a manifestJisting access controls for each electronic data file stored 
in the data repository and a\ecord Ustingsdocument access privileges for each computer with 
access to the electronic data stored in the repository, the process comprising the steps of: 

updating a manifest for an electronic data ffl^ stored in the repository; 

identifying all computers wi/h a^jjiangfe in acce^ to the electronic data file effected by the 
update; ^ 

\ 

communicating the change in access tp all affected computes; 
updating the access privileges records o\all affected compilers; and 
communicating the updated access privileg&xecords to the affe^ed computers. 
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A secure system for searching electronic data files stored in a data repository system, 
com^sing: 

mejb^ for maintaining a manifest listing access controls for each electronic data file stored 
in the data repository system; 

means for restrifctrng access to each manifest to a computer with deposit privileges; 

means for maintaining^ record listing access privileges to the electronic data files 
associated with each computer wit^aqcess privileges to at least one electronic data file in the data 
repository system; \^ 

means for restricting access to each sakkrecord to the associated computer with access 
privileges; and 

means for updating the record associated with each ccmiputer affected by an access change 
in a manifest. 
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A computer program product on a computer usable medium for maintaining a secure 
elecfrqnic data search system for an electronic data repository, the system having a manifest 
listing access controls for each electronic data file stored in the data repository and a record listing 
document accfe^s privileges for each computer with access to electronic data stored in the 
repository, the program product comprising: 

software for updatihga manifest for an electronic data file stored in the repository; 

software for identifying alSqomputers with a change in access to the electronic data file 
effected by the update; Nn \ s ^ 

software for communicating the changfcsm access to all affected computers; 

software for updating the access privileges refers of all affected computers; and 

software for communicating the updated accesKprivilege records to the affected 
computers. 
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